6.5
CVSSv2

CVE-2012-1037

Published: 12/07/2012 Updated: 16/07/2012
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 up to and including 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

glpi-project glpi 0.80

glpi-project glpi 0.80.1

glpi-project glpi 0.80.2

glpi-project glpi 0.80.3

glpi-project glpi 0.78

glpi-project glpi 0.78.1

glpi-project glpi 0.78.3

glpi-project glpi 0.78.5

glpi-project glpi 0.80.4

glpi-project glpi 0.80.6

glpi-project glpi 0.78.2

glpi-project glpi 0.78.4

glpi-project glpi 0.80.5

glpi-project glpi 0.80.61

Exploits

GLPI versions 08061 and below suffer from local file inclusion and remote file inclusion vulnerabilities ...